OESA-2026-3664

    Dashboard / Vulnerabilities / OESA-2026-3664

    OESA-2026-3664

    Published: 5 Sept 2026Last Modified: 5 Sept 2026
    Upstream:

    Summary: NetworkManager security update

    Details: NetworkManager attempts to keep an active network connection available at all times. The point of NetworkManager is to make networking configuration and setup as painless and automatic as possible. If using DHCP, NetworkManager is intended to replace default routes, obtain IP addresses from a DHCP server, and change name servers whenever it sees fit. Security Fix(es): NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.(CVE-2026-19685)

    Affected packages

    Package

    Name: NetworkManager

    Purl: pkg:rpm/openEuler/NetworkManager&distro=openEuler-20.03-LTS-SP4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.26.2-19.oe2003sp4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2026-3664 | CVE-DB